Creating a key
The app generates the key in your browser and shows it once, with ready-made blocks for an env file, the MCP config and the SDK. Then it calls addAgent(key, label, dailyLimit, perCallMax, expiry) from your wallet. Only the public address goes on chain. updateAgent changes the limits; revokeAgent turns the key off.
Active key
0x9A3f…c41E
Revoked
0x51b0…07aD
Every payment it signs reverts with AgentInactive, including the ones it signed before you revoked it.
Where the key lives
The agent reads it from OTSUKAI_KEY and the account from OTSUKAI_ACCOUNT. Keep it out of prompts and logs. It needs no ETH: whoever submits the payment pays the gas.
Payees
setPayee(payee, allowed, label) manages the allow-list of the account. It is per account, not per key. Otsukai's endpoints can be added in one click from the app; any other address with a label.
If a key leaks
The most a leaked key can do is pay your listed payees up to what is left of its daily limit, until it expires or you revoke it. It can never pay anyone else and never touch the rest of the balance. Limits are the defence, so keep them close to what the agent really needs.